| IP | Événements |
|---|---|
198.51.100.20 | 6 |
198.51.100.11 | 6 |
198.51.100.33 | 6 |
198.51.100.24 | 6 |
198.51.100.17 | 5 |
198.51.100.29 | 5 |
198.51.100.14 | 4 |
198.51.100.34 | 4 |
198.51.100.35 | 4 |
198.51.100.28 | 4 |
| URI | Événements |
|---|---|
/?q=../../etc/passwd | 15 |
/api/v1/login | 15 |
/wp-login.php | 14 |
/xmlrpc.php | 13 |
/.env | 11 |
/index.php?id=1 | 9 |
/admin/ | 8 |
| ID de la règle | Déclenchements |
|---|---|
932100RCE — Unix commands |
21 |
913100Security scanner — User-Agent |
18 |
941100XSS via libinjection |
16 |
930100Path Traversal (/../) |
15 |
942100SQL Injection via libinjection |
15 |
| Heure | IP | URI | Type | Règle | Action |
|---|---|---|---|---|---|
| 2026-10-12 00:40:27 | 198.51.100.14 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-12 00:34:30 | 198.51.100.31 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-12 00:26:29 | 198.51.100.20 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 23:10:54 | 198.51.100.11 |
/admin/ |
RCE | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 22:53:39 | 198.51.100.19 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 23:50:27 | 198.51.100.26 |
/wp-login.php |
XSS | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 22:53:39 | 198.51.100.11 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 21:04:58 | 198.51.100.34 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 20:58:51 | 198.51.100.34 |
/index.php?id=1 |
RCE | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 23:12:42 | 198.51.100.17 |
/.env |
RCE | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 23:42:07 | 198.51.100.13 |
/?q=../../etc/passwd |
Protocol Attack | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 20:05:05 | 198.51.100.15 |
/xmlrpc.php |
Scanner | 941100 XSS via libinjection |
Bloqué |
| 2026-10-11 21:30:15 | 198.51.100.25 |
/?q=../../etc/passwd |
XSS | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 22:17:01 | 198.51.100.35 |
/.env |
Scanner | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 22:10:11 | 198.51.100.11 |
/api/v1/login |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 16:50:27 | 198.51.100.20 |
/index.php?id=1 |
Protocol Attack | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 23:46:35 | 198.51.100.28 |
/wp-login.php |
XSS | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 18:52:48 | 198.51.100.22 |
/wp-login.php |
Scanner | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 20:57:51 | 198.51.100.32 |
/xmlrpc.php |
Scanner | 942100 SQL Injection via libinjection |
Bloqué |
| 2026-10-11 20:40:06 | 198.51.100.22 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 21:04:07 | 198.51.100.18 |
/xmlrpc.php |
RCE | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 14:16:24 | 198.51.100.12 |
/api/v1/login |
LFI/Path Traversal | 941100 XSS via libinjection |
Bloqué |
| 2026-10-11 20:28:33 | 198.51.100.16 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 21:31:05 | 198.51.100.33 |
/api/v1/login |
XSS | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 11:23:15 | 198.51.100.35 |
/.env |
RCE | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 21:48:22 | 198.51.100.12 |
/wp-login.php |
Protocol Attack | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 19:43:11 | 198.51.100.16 |
/admin/ |
SQL Injection | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 15:35:03 | 198.51.100.23 |
/wp-login.php |
XSS | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 15:39:35 | 198.51.100.24 |
/wp-login.php |
Scanner | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 11:37:27 | 198.51.100.30 |
/api/v1/login |
XSS | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 15:08:57 | 198.51.100.14 |
/index.php?id=1 |
LFI/Path Traversal | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 12:23:10 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 10:13:15 | 198.51.100.20 |
/.env |
SQL Injection | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 15:16:42 | 198.51.100.33 |
/.env |
Protocol Attack | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 13:46:31 | 198.51.100.17 |
/.env |
SQL Injection | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 06:30:12 | 198.51.100.25 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 15:05:03 | 198.51.100.12 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 16:49:56 | 198.51.100.21 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 17:03:49 | 198.51.100.28 |
/admin/ |
SQL Injection | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 13:21:12 | 198.51.100.20 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 17:19:47 | 198.51.100.34 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Bloqué |
| 2026-10-11 15:09:11 | 198.51.100.24 |
/admin/ |
RCE | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 15:51:15 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 20:23:53 | 198.51.100.13 |
/?q=../../etc/passwd |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 19:28:03 | 198.51.100.17 |
/index.php?id=1 |
XSS | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 20:57:42 | 198.51.100.35 |
/.env |
Scanner | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 17:01:59 | 198.51.100.14 |
/xmlrpc.php |
XSS | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 13:00:09 | 198.51.100.11 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 08:33:15 | 198.51.100.33 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 20:39:32 | 198.51.100.17 |
/wp-login.php |
XSS | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 17:39:37 | 198.51.100.33 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 10:32:09 | 198.51.100.26 |
/api/v1/login |
Scanner | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-11 15:59:35 | 198.51.100.28 |
/.env |
LFI/Path Traversal | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 13:53:51 | 198.51.100.32 |
/api/v1/login |
Protocol Attack | 930100 Path Traversal (/../) |
Bloqué |
| 2026-10-11 07:38:57 | 198.51.100.23 |
/index.php?id=1 |
Protocol Attack | 942100 SQL Injection via libinjection |
Bloqué |
| 2026-10-11 14:31:47 | 198.51.100.24 |
/admin/ |
RCE | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 11:37:23 | 198.51.100.35 |
/?q=../../etc/passwd |
SQL Injection | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-11 13:41:09 | 198.51.100.20 |
/?q=../../etc/passwd |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-10 19:31:45 | 198.51.100.21 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 13:57:21 | 198.51.100.11 |
/?q=../../etc/passwd |
Scanner | 913100 Security scanner — User-Agent |
Bloqué |
| 2026-10-11 05:44:27 | 198.51.100.19 |
/?q=../../etc/passwd |
XSS | 930100 Path Traversal (/../) |
Bloqué |
| 2026-10-11 13:34:32 | 198.51.100.21 |
/?q=../../etc/passwd |
XSS | 941100 XSS via libinjection |
Bloqué |
| 2026-10-10 18:40:23 | 198.51.100.24 |
/index.php?id=1 |
LFI/Path Traversal | 941100 XSS via libinjection |
Détecté |
| 2026-10-10 15:02:21 | 198.51.100.29 |
/index.php?id=1 |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Bloqué |
| 2026-10-10 14:05:47 | 198.51.100.15 |
/admin/ |
RCE | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 19:38:12 | 198.51.100.29 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 20:02:09 | 198.51.100.17 |
/xmlrpc.php |
RCE | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 17:49:31 | 198.51.100.20 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Détecté |
| 2026-10-10 16:20:11 | 198.51.100.24 |
/api/v1/login |
Scanner | 941100 XSS via libinjection |
Bloqué |
| 2026-10-11 10:20:15 | 198.51.100.19 |
/.env |
Scanner | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 18:37:37 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Bloqué |
| 2026-10-10 13:22:17 | 198.51.100.12 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 16:10:27 | 198.51.100.28 |
/wp-login.php |
XSS | 942100 SQL Injection via libinjection |
Détecté |
| 2026-10-10 11:37:36 | 198.51.100.33 |
/.env |
RCE | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 04:12:03 | 198.51.100.18 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 15:42:57 | 198.51.100.26 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Bloqué |
| 2026-10-11 09:13:15 | 198.51.100.14 |
/admin/ |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-10 10:43:49 | 198.51.100.33 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Détecté |
| 2026-10-11 03:29:03 | 198.51.100.27 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Détecté |
| 2026-10-11 07:09:45 | 198.51.100.11 |
/.env |
SQL Injection | 941100 XSS via libinjection |
Bloqué |
| 2026-10-11 12:32:27 | 198.51.100.34 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Bloqué |
| 2026-10-11 19:31:18 | 198.51.100.24 |
/api/v1/login |
Protocol Attack | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 11:20:57 | 198.51.100.32 |
/xmlrpc.php |
Scanner | 942100 SQL Injection via libinjection |
Bloqué |
| 2026-10-11 03:02:53 | 198.51.100.32 |
/admin/ |
Protocol Attack | 932100 RCE — Unix commands |
Détecté |
| 2026-10-11 05:29:39 | 198.51.100.27 |
/wp-login.php |
Scanner | 913100 Security scanner — User-Agent |
Détecté |
ModSecurity avec l’OWASP Core Rule Set bloque beaucoup de choses, et écrit à peu près tout dans un journal d’audit conçu pour les machines. Cette page en fait quelque chose de lisible : quelles requêtes ont été bloquées, quelle règle s’est déclenchée, quel était le score d’anomalie et d’où venait la requête.
La raison d’y revenir régulièrement, ce sont les faux positifs. Le Core Rule Set est volontairement strict et, au niveau de paranoïa par défaut, il bloquera du trafic légitime dans la plupart des applications réelles — envois de fichiers, éditeurs de texte enrichi et tout ce qui poste du balisage ou des chaînes ressemblant à du SQL en font les frais. Le motif à repérer : le même identifiant de règle qui se déclenche à répétition sur le même point d’entrée depuis de nombreuses adresses différentes. Ce n’est pas une attaque, c’est votre propre application qui se fait prendre.
Dans ce cas, l’exception doit rester étroite : exclure la règle précise, pour le paramètre précis, sur le chemin précis — jamais la règle entière et encore moins la catégorie. La page liste aussi le jeu de règles actif, pour vérifier après coup ce qui est réellement chargé.